Who is Trace3?Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to our clients. Equipped with elite engineering and dynamic innovation, we empower IT executives and their organizations to achieve competitive advantage through a process of Integrate, Automate, Innovate.Our culture at Trace3 embodies the spirit of a startup with the advantage of a scalable business. Employees can grow their career and have fun while doing it!Trace3 is headquartered in Irvine, California. We employ more than 1,200 people all over the United States. Our major field office locations include Denver, Indianapolis, Grand Rapids, Lexington, Los Angeles, Louisville, Texas, San Francisco. JOB SUMMARY:The Solutions Architect, Governance, Risk, & Compliance, is a client-facing practice expert who combines delivery experience, GRC subject-matter expertise, and thought leadership on the security best practices and programs for Trace3 clients. This role leads complex consulting engagements, advises CIOs, CISOs, risk leaders, privacy leaders, and other executive stakeholders, and helps clients establish resilient, scalable, and compliant security programs.The Solution Architect, GRC, will provide education and direction on security, risk, privacy, resilience, technologies, compliance, and AI governance. The role also supports the full sales cycle, including opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations. A key function of this role will be to build deep relationships, gain trust, and enable client success.SUMMARY OF ESSENTIAL JOB FUNCTIONS:Lead complex GRC, security, privacy, risk, and AI engagementsFacilitate client workshops to provide education and expertise with clients and executive stakeholders.Assess current-state capabilities across people, process, and technology and define practical target states, priorities, dependencies, and implementation roadmaps.Apply leading frameworks and regulations, including NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC, as appropriate to the client environment.Translate regulatory and security requirements into tailored control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable program objectives.Oversee high-quality deliverables, including assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.Maintain trusted relationships with client sponsors, decision-makers, control owners, and partner teams.Advise organizations on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.Monitor and inform the practice and its clients on emerging and applicable AI laws, regulations, regulatory guidance, standards, and contractual requirements, including the EU AI Act, U.S. federal and state developments, GDPR-related obligations, and sector-specific requirements.Translate evolving AI requirements into practical policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.Help define, mature, package, and operationalize Trace3’s GRC service portfolio and delivery methodologies.Establish reusable approaches, templates, quality standards, and intellectual property that improve consistency, scalability, and client outcomes.Serve as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published content.Track GRC-adjacent technologies and build partnerships with solution/market leaders on capabilities across control management, trust centers, third-party risk management, risk management, privacy operations, and AI governance.REQUIRED SKILLS AND EXPERIENCE:Bachelor’s degree from an accredited university requiredMinimum of 10-15 years’ experience in security consultingMinimum of 10-15 years’ experience in enterprise securityCISSP, CISA, CISM, CIPP or equivalent security or privacy certification strongly desiredStrong expertise in assessing the maturity of IT security programs and capabilities to identify a security program’s current state and establishing a roadmap for achieving a defined target state, which accounts for noted capability gaps and affiliated risksExtensive knowledge in industry security and risk management frameworks/guidance (e.g., NIST CSF, ISO 27001, ISO 27005, NIST Risk Management Framework, etc.) and extensive experience implementing or assessing against themExperience performing IT/IS risk, privacy, and control assessments based on leading practice and regulatory requirements (e.g., PCI, SOC2, GDPR, HIPAA)Working knowledge of both industry best practices and regulatory/compliance landscape across common cybersecurity domainsMotivated self-starter who loves to solve challenging problems and feels comfortable working directly with customersExcellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience, advanced PowerPoint presentation skills strongly desiredHighly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environmentAbility to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliverComfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environmentAbility to travel when neededEstimated Pay Range$170,000 - $200,000 USDThe PerksComprehensive medical, dental and vision plans for you and your dependents401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term DisabilityCompetitive CompensationTraining and development programsMajor offices stocked with snacks and beveragesCollaborative and cool cultureWork-life balance and generous paid time offOur CommitmentAt the core of Trace3's DNA is our people. We are a diverse group of talented individuals who understand the importance of teamwork and demonstrating leadership, character, and passion in all that we do.We’re committed to fostering an inclusive workplace where everyone feels respected, valued, and empowered to grow. We recognize that embracing diversity drives innovation, improves outcomes, fosters collaboration, boosts teammate satisfaction, and builds a more inclusive culture.As an equal opportunity employer, Trace3 bases all employment decisions based on individual qualifications, merit, and business requirements. We do not engage in discrimination on the basis of race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability, genetic information, or any other characteristic protected by federal, state, or local law.Any demographic information provided is strictly voluntary, kept confidential in accordance with Equal Employment Opportunity (EEO) regulations, and will not be used in employment decisions, including hiring, promotions, or mentorship programs. We are committed to providing equal employment opportunities for all.If you require a reasonable accommodation to complete the application process or participate in an interview, please email
recruiting@trace3.com.